SPF Record Generator

SPF Record Generator

Combine mail providers, server IPs and DNS mechanisms into one SPF TXT record.

Common sending providers
Additional authorization
Default policy

TXT hostname

@

TXT record value

v=spf1 ~all

Direct DNS mechanisms

0 / 10

Record length

11 chars

  • Enter a valid domain.

Sender authorization generator

What is an SPF record?

SPF is a TXT policy at the domain root that lists servers authorized to send mail for the domain. Receivers compare the connecting IP with that policy.

This generator combines common providers, custom includes, IP addresses and optional A or MX mechanisms into one v=spf1 value and displays the visible DNS mechanism budget.

Sending sources you can combine

SaaS

Common mail providers

Select Google, Microsoft, Zoho, Mailchimp, SendGrid and Amazon SES.

IP

Server addresses

Add IPv4 or IPv6 ranges plus optional A and MX authorization.

DNS

Lookup budget guidance

Count direct include, a and mx mechanisms while flagging recursive risk.

Why generate one SPF record?

Multiple v=spf1 records cause PermError. Too many include mechanisms can exceed the ten-DNS-lookup limit and invalidate authorization.

Combine all senders

Keep mail platforms and owned servers in one maintainable policy.

Control DNS mechanisms

Review direct lookup mechanisms and potential recursive risk before publishing.

Choose an explicit ending

Use -all, ~all or ?all for the rollout stage instead of omitting all.

How should the generated SPF be deployed?

Find the current SPF first. If one exists, merge the mechanisms instead of adding a second record.

  1. 01

    List every sender

    Include business email, marketing, ticketing and owned servers.

  2. 02

    Select providers and add IPs

    Authorize active sources only and remove retired platforms.

  3. 03

    Review budget and length

    Direct count is not the full recursive count, so test after publishing.

  4. 04

    Merge and publish one value

    Keep one v=spf1 TXT record at the root and verify it with the checker.

SPF generator FAQ

Why can a domain have only one SPF record?

SPF evaluation expects one policy. Multiple v=spf1 records cannot be reliably combined and cause PermError.

What counts toward the ten DNS lookups?

include, a, mx, exists, redirect and deprecated ptr can trigger lookups. Includes may recurse. This tool shows the direct budget; test the deployed record for the complete count.

What is the difference between -all and ~all?

-all marks unauthorized sources as fail and suits a confirmed sender inventory. ~all is softfail and is often used during migration or observation.

Does SPF stop all domain spoofing?

No. SPF authenticates the envelope domain and connecting IP. DKIM and DMARC alignment are also needed to protect the visible From domain.

Does the generator read an existing SPF record?

No. It combines input locally. Check the current DNS record first and merge it manually before publishing.